SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-54590

MEDIUM · CVSS 5.9 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The AsyncSSH Python package version 2.23.0 has a vulnerability in the SSHServerConfig._set_tokens function that allows unauthorized file path expansions, potentially leading to unauthorized access to the authorized-keys directory. This flaw arises from insufficient input validation, specifically failing to block leading tilde (~) or environment variable substitutions. Users of AsyncSSH, particularly those managing SSH servers, should prioritize upgrading to version 2.23.1 to mitigate this security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54590
Severity
MEDIUM
CVSS
5.9
EPSS
0.29%

Original NVD Description

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.